Everyday IT · Security

Unexpected MFA is a security signal, not just a login problem.

When a user reports an MFA prompt they did not initiate, an unfamiliar sign-in, or suspicious mailbox behavior, switch from routine authentication troubleshooting to evidence-driven first response.Do not weaken MFA to make the symptom disappear.

First-response path

Preserve security while you determine whether the activity is expected, stale, or malicious.

01

Verify the person

Confirm the user through an approved channel before changing credentials, authentication methods, forwarding, or mailbox settings.

02

Pin down the event

Capture the approximate time, device, location, application, prompt type, and whether the user initiated a sign-in at that moment.

03

Review sign-in evidence

Look for unfamiliar devices, locations, impossible timing, repeated failures, risk indicators, or authentication events that do not match the user's explanation.

04

Check mailbox and account changes

If compromise is plausible, review suspicious forwarding, inbox rules, delegates, recovery methods, and other account changes using the approved security process.

05

Contain only with authority

Use the organization's approved response path for password reset, session revocation, method recovery, or account restriction. Do not improvise broad tenant changes.

06

Escalate with evidence

Hand off the exact event, what is confirmed, what changed, containment already performed, and what remains unknown.

What not to do

Do not disable MFA tenant-wide

A suspicious prompt is not evidence that MFA is the problem.

Do not blindly delete methods

Removing authentication methods without understanding ownership and recovery can make the incident harder to contain.

Do not trust one successful login as proof

The legitimate user being able to sign in does not rule out another active session or account change.

Escalate early on privileged identities

Administrator, finance, executive, or shared-service identities deserve a lower threshold for formal incident handling.

Unexpected authentication activity changes the ticket from “make login work” to “prove who is signing in.”

Related Guides

Keep the next action inside the approved security process.

Scope

Determine who and what is affected

Separate one prompt or identity from a pattern involving multiple users, devices, locations, or services. Scope the problem

Change

Protect the recovery path

Before resetting credentials, revoking sessions, or changing authentication methods, define authority, impact, and rollback. Plan the change safely

Escalate

Hand off the security evidence

If compromise is plausible or the identity is privileged, preserve the timeline, findings, containment state, and exact unresolved risk. Escalate with evidence